Terminal identity traceability method, device and computer-readable storage medium
By analyzing the traffic of N4 and N3 interfaces and generating terminal tunnels and load tables, the problem of terminal identity traceability in 5G networks is solved, accurate positioning of attack terminals is achieved, and network security is improved.
Patent Information
- Application Number
- CN202210177790.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-25
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-02-25
AI Technical Summary
In 5G networks, it is difficult for the prior art to identify the identity of the attack terminal in the service domain, and it is impossible to trace the terminal corresponding to the attack flow.
By analyzing the session management process traffic of the N4 interface, establishing a terminal tunnel table, analyzing the service traffic of the N3 interface, establishing a tunnel load table, and combining the terminal tunnel table with the tunnel load table to generate a terminal load table, realizing the association of terminal identity information and load stream information, and performing security detection to trace the attack flow.
It realizes traceability and positioning of terminal identity in a 5G private network environment, improves the closed-loop effect of network protection, and can accurately locate attack terminals.
Smart Images

Figure CN114423008B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to, but are not limited to, the field of mobile communication technologies, and in particular, to a terminal identity tracing method, device, and computer-readable storage medium. Background Art
[0002] The architecture of the 5G network is different from that of the conventional Internet. The terminal access to the network is divided into the signaling domain and the service domain. The signaling domain is the signaling interaction between the terminal and the 5G core network. The terminal needs to be authenticated through the signaling domain before accessing the network. After the authentication is passed, the 5G core network will assign a temporary identity (5G Globally Unique Temporary Identifier, 5G-GUTI), and interact with the signaling domain through this temporary identity. In order to ensure the terminal business communication, the authenticated terminal will also be assigned a service tunnel, and the business domain will transmit business traffic through the assigned tunnel. If a terminal launches an attack, by monitoring the business domain traffic, even if the attack is identified, it is impossible to determine the terminal corresponding to the attack flow. Summary of the invention
[0003] The embodiments of the present disclosure provide a terminal identity tracing method, device and computer-readable storage medium, which can trace and locate the terminal identity in a 5G private network environment.
[0004] The embodiment of the present disclosure provides a terminal identity tracing method, comprising: parsing the session management process traffic of the N4 interface to establish a terminal tunnel table, wherein the terminal tunnel table is used to record the identity information of the terminal and the tunnel information allocated to the terminal; parsing the service traffic of the N3 interface to establish a tunnel load table, wherein the tunnel load table is used to record the tunnel information and the load flow information of the tunnel; establishing a terminal load table based on the terminal tunnel table and the tunnel load table, wherein the terminal load table is used to record the identity information of the terminal and the load flow information corresponding to the terminal; and detecting the load flow information to be detected based on the terminal load table.
[0005] In some exemplary embodiments, the session management process includes a session creation process and a session modification process, and the parsing of the session management process traffic of the N4 interface includes: parsing the session creation process traffic of the N4 interface, recording the identity information of the terminal, the uplink tunnel information assigned to the terminal, and the session layer information of the current session process; parsing the session modification process traffic of the N4 interface, and determining the downlink tunnel information of the terminal based on the session layer information of the current session process.
[0006] In some exemplary embodiments, the uplink tunnel information includes the tunnel endpoint identifier of the uplink tunnel and the destination IP address for the uplink tunnel communication, and the downlink tunnel information includes the tunnel endpoint identifier of the downlink tunnel and the destination IP address for the downlink tunnel communication.
[0007] In some exemplary embodiments, the session layer information of the current session process includes: the session endpoint identifier of the current session process and the session IP address.
[0008] In some exemplary embodiments, the load flow information includes the source IP address, the destination IP address, the source port number, and the destination port number.
[0009] In some exemplary embodiments, the load flow information includes the source IP address, the destination IP address, the source port number, the destination port number, and the protocol number.
[0010] In some exemplary embodiments, the identity information of the terminal includes the international mobile subscriber identification number or the user permanent identifier of the terminal.
[0011] In some exemplary embodiments, detecting the load flow information to be detected according to the terminal load table includes: performing a security detection on the tunnel load flow of the N3 interface; when a security attack is detected, obtaining the attack flow information; and determining the terminal corresponding to the attack flow information according to the terminal load table.
[0012] Embodiments of the present disclosure further provide a terminal identity tracing device, including a memory; and a processor connected to the memory, where the processor is configured to execute the steps of the terminal identity tracing method as described in any one of the above based on instructions stored in the memory.
[0013] Embodiments of the present disclosure further provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the terminal identity tracing method as described in any one of the above.
[0014] The terminal identity tracing method, device, and computer storage medium according to the embodiments of the present disclosure parse the traffic of the session management process of the N4 interface to establish a terminal tunnel table; parse the service traffic of the N3 interface to establish a tunnel load table; establish a terminal load table according to the terminal tunnel table and the tunnel load table, and detect the load flow information to be detected according to the terminal load table, thereby realizing the tracing and positioning of the terminal identity in the 5G private network environment, and being able to help the network protection of the 5G private network achieve a closed-loop effect.
[0015] Other features and advantages of the present disclosure will be set forth in the following description, and in part will be obvious from the description, or can be learned by practicing the present disclosure. Other advantages of the present disclosure can be realized and obtained by the solutions described in the description and the drawings. Description of the Drawings
[0016] The drawings are used to provide an understanding of the technical solutions of the present disclosure, and constitute a part of the description. Together with the embodiments of the present disclosure, they are used to explain the technical solutions of the present disclosure, and do not constitute a limitation to the technical solutions of the present disclosure.
[0017] Figure 1 It is a schematic structural diagram of a 5G system;
[0018] Figure 2 It is a schematic flowchart of a method for tracing the identity of a terminal according to an exemplary embodiment of the present disclosure;
[0019] Figure 3 It is a schematic diagram of a session management process between an SMF network element and a UPF network element;
[0020] Figure 4 It is a schematic flowchart of another method for tracing the identity of a terminal according to an exemplary embodiment of the present disclosure;
[0021] Figure 5 It is a modular schematic diagram of a device for tracing the identity of a terminal according to an exemplary embodiment of the present disclosure;
[0022] Figure 6 It is a schematic structural diagram of a device for tracing the identity of a terminal according to an exemplary embodiment of the present disclosure. Detailed Embodiments
[0023] To make the objectives, technical solutions, and advantages of the present disclosure clearer and more understandable, the embodiments of the present disclosure will be described in detail below with reference to the drawings. It should be noted that, without conflict, the embodiments and features in the present disclosure can be combined with each other arbitrarily.
[0024] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meanings understood by those of ordinary skill in the art to which the present disclosure belongs. The terms "first", "second", and similar terms used in the embodiments of the present disclosure do not indicate any order, quantity, or importance, but are only used to distinguish different components. The terms such as "include" or "comprise" mean that the elements or items before this word cover the elements or items listed after this word and their equivalents, without excluding other elements or items.
[0025] The architecture of the Fifth Generation (5G) mobile communication system consists of several Network Functions (NFs). Among them, the Session Management Function (SMF) is a control plane network element that can manage the establishment, modification, and release of sessions, and can also allocate and manage the IP of user terminals. The User Plane Function (UPF) is a data plane network element that can serve as the mobile anchor for Radio Access Technology (RAT), can also allocate the IP of user terminals in response to requests from the SMF network element, can also serve as the connection point between the Protocol Data Unit (PDU) session and the external data network (DN), and can also perform packet routing and forwarding. The N4 interface is the interface between the SMF network element and the UPF network element. In the process of establishing the PDU Session of the User Equipment (UE), the N4 Session, also known as the PFCP Session, will be established synchronously. The application layer protocol of the N4 interface uses the Packet Forwarding Control Protocol (PFCP) protocol, which is used to define the ways for the UPF network element to identify, forward, cache, mark, report, and multi-access PDUs.
[0026] As Figure 1 shown, the 5G private network network structure includes terminals, base stations, 5G core networks, UPF network elements, Multi-Access Edge Computing (MEC) network elements, etc. Among them, the terminal is the user equipment. After the 5G core network authenticates the terminal when it accesses the Internet, the SMF network element and the UPF network element establish a session tunnel for each terminal through the N4 interface. This tunnel is used for communication between the base station and the UPF network element (through the N3 interface). The N4 interface uses the PFCP protocol for terminal session management. Terminal session management is divided into a session creation process, a session modification process, and a session deletion process. The N3 interface uses the GTP (GPRS Tunneling Protocol) as the tunnel protocol, and the service data of the terminal is transmitted through the tunnel payload. The access information of the terminal is transmitted through the tunnel. Ordinary network security devices can strip the tunnel and then perform traffic security monitoring on the real user traffic, but it is usually difficult to trace and locate the attacking terminal.
[0027] To perform terminal traceability, it is necessary to combine the authentication process of the terminal in the 5G private network. However, the terminal identity traceability method of the present disclosure only needs to collect the traffic of the N3 interface and the N4 interface to perform the traceability positioning of the attack traffic in the service domain.
[0028] As Figure 2 shown, the embodiments of the present disclosure provide a terminal identity traceability method, including:
[0029] Step 201: Parse the traffic of the session management process of the N4 interface to establish a terminal tunnel table, which is used to record the identity information of the terminal and the tunnel information allocated to the terminal;
[0030] In some exemplary embodiments, the session management process may include a session creation process, a session modification process, and a session deletion process.
[0031] In this embodiment, as Figure 3 shown, by exporting all the signaling packets of the communication between the SMF network element and the UPF network element, the session establishment request message (Session Establishment Request) sent by the SMF network element to the UPF network element, the session establishment response message (Session Establishment Response) returned by the UPF network element to the SMF network element, the session modification request message (Session Modification Request) sent by the SMF network element to the UPF network element, the session modification response message (Session Modification Response) returned by the UPF network element to the SMF network element, the session deletion request message (Session Deletion Request) sent by the SMF network element to the UPF network element, and the session deletion response message (Session Deletion Response) returned by the UPF network element to the SMF network element can be obtained.
[0032] The session establishment request message is mainly used when the terminal has an Internet access requirement. The SMF network element sends a request to the UPF network element to let the UPF establish (or the SMF establishes and notifies the UPF) the uplink tunnel for the terminal to access the Internet. The session modification request message is also a request sent by the SMF to the UPF, which is used to notify the UPF of the downlink tunnel established by the base station for the terminal to access the Internet. Among them, the uplink tunnel refers to the tunnel from the base station to the UPF network element, and the downlink tunnel refers to the tunnel from the UPF network element to the base station. Each tunnel has a tunnel endpoint identifier (Tunnel Endpoint Identifier, TEID) and the destination IP address for tunnel communication.
[0033] In some exemplary embodiments, the session establishment request message may carry the identity information of the terminal. Exemplarily, the identity information of the terminal may include the identity document (ID) of the terminal. The identity identifier of the terminal may include: the International Mobile Subscriber Identity (IMSI) of the terminal or the Subscription Permanent Identifier (SUPI).
[0034] In a telecommunications system, the network operator assigns a unique identifier to each SIM card, which was called IMSI before 4G and SUPI in 5G. Since the authentication between the user and their network provider is based on a shared symmetric key, it can only be performed after the user identity is known. However, if the IMSI / SUPI value is sent in plain text over the radio access link, these permanent identifiers can be used to identify, locate, and track the user.
[0035] To avoid such privacy leakage, the access network assigns a temporary identifier (called the Temporary Mobile Subscriber Identity (TMSI) until the 3G system and the Globally Unique Temporary Identifier (GUTI) for 4G and 5G systems) to the terminal. These frequently changed temporary identifiers are then used for identification purposes on the radio access link. However, in some cases, authentication cannot be performed using the temporary identifier, such as when the user first registers on the network and no temporary identifier has been assigned yet, or another case is that the access network cannot resolve the IMSI / SUPI.
[0036] In some exemplary embodiments, the session establishment request message may also carry the Session Endpoint Identifier (SEID) assigned by the SMF network element to the UPF network element and the session IP address (the SEID and the session IP address are used to associate the session modification process, and the session IP address is the destination IP address of the session modification request message), etc.
[0037] In some exemplary embodiments, the session establishment request message may also carry the Tunnel Endpoint Identifier (TEID) of the UPF network element and the destination IP address of the uplink tunnel communication.
[0038] The SMF network element can determine whether the response is successful based on the session establishment response message returned by the UPF network element.
[0039] In some exemplary embodiments, the session modification request message sent by the SMF network element to the UPF network element may carry the SEID assigned by the SMF network element to the UPF network element and the session IP address (the SEID is the same as the SEID in the session establishment request message and the destination IP address of the session modification request message is the session IP address in the session establishment request message), the TEID of the base station (gNB), and the destination IP address of the downlink tunnel communication, etc.
[0040] The SMF network element may determine whether the response is successful according to the session modification response message.
[0041] In some exemplary embodiments, parsing the traffic of the session management process for the N4 interface may include the following steps:
[0042] Parse the traffic of the session creation process for the N4 interface, record the identity information of the terminal, the uplink tunnel information assigned to the terminal, and the session layer information of the current session process;
[0043] Parse the traffic of the session modification process for the N4 interface, and determine the downlink tunnel information of the terminal according to the session layer information of the current session process.
[0044] Exemplarily, the uplink tunnel information includes the tunnel endpoint identifier of the uplink tunnel and the destination IP address of the uplink tunnel communication.
[0045] Exemplarily, the downlink tunnel information includes the tunnel endpoint identifier of the downlink tunnel and the destination IP address of the downlink tunnel communication.
[0046] Exemplarily, the session layer information of the current session process includes: the session endpoint identifier of the current session process and the session IP address (i.e., the destination IP address of the session modification request message).
[0047] In this embodiment, by parsing the traffic of the session creation process and the session modification process for the N4 interface, if the SEID and the session IP address carried in the message of the session creation process are the same as the SEID and the session IP address carried in the message of the session modification process, it indicates that the session creation process and the session modification process belong to the associated processes of the same terminal, and from the message of the session creation process, the identity information of the terminal and the uplink tunnel information of the terminal can be obtained, and from the message of the session modification process, the downlink tunnel information of the terminal can be obtained.
[0048] Step 202: Parse the service traffic of the N3 interface to establish a tunnel load table, which is used to record the tunnel information and the load flow information of the tunnel;
[0049] GTP is a set of IP-based high-level protocols that are located on top of protocols such as TCP / IP or UDP / IP. It is mainly used to support the communication protocols of General Packet Radio Service (GPRS) in GSM, UMTS, and LTE networks. The GTP protocol is mainly divided into the GTP-C and GTP-U protocols. Among them, GTP-C belongs to the control layer protocol and is used to transmit signaling between the Gateway GPRS Support Node (GGSN) and the Serving GPRS Support Nodes (SGSN) within the GPRS core network, for establishing, managing, using, and releasing request information; GTP-U belongs to the transport layer protocol and is used to transmit user data between the radio access and the core network within the GPRS core network. The N3 interface transmits user plane data, which is basically GTP-U data.
[0050] In some exemplary embodiments, the traffic flow information may include the quadruple information of the flow, that is, the source IP address, the destination IP address, the source port number, and the destination port number.
[0051] In some other exemplary embodiments, the traffic flow information may include the quintuple information of the flow, that is, the source IP address, the destination IP address, the source port number, the destination port number, and the transport layer protocol number.
[0052] Step 203: Establish a terminal traffic load table according to the terminal tunnel table and the tunnel traffic load table. The terminal traffic load table is used to record the identity information of the terminal and the traffic flow information corresponding to the terminal.
[0053] In this embodiment, by associating the information of the terminal tunnel table generated in step 201 with the tunnel traffic load table generated in step 202, a terminal traffic load table is generated, and the terminal traffic load table is updated in real time according to the changes.
[0054] Step 204: Detect the traffic flow information to be detected according to the terminal traffic load table.
[0055] In some exemplary embodiments, detecting the traffic flow information to be detected according to the terminal traffic load table includes:
[0056] Perform security detection on the tunnel traffic flow of the N3 interface;
[0057] When a security attack is detected, obtain the attack flow information;
[0058] Determine the terminal corresponding to the attack flow information according to the terminal traffic load table.
[0059] The terminal identity tracing method proposed in this disclosure can be used not only for terminal tracing of the source of the attack flow, but also for any other scenarios that require terminal tracing. The embodiments of this disclosure do not limit this.
[0060] The terminal identity traceability method proposed by the present disclosure includes traffic analysis of the N3 interface and the N4 interface, and traffic association between the N3 interface and the N4 interface. Among them, traffic analysis is to determine the terminal information, tunnel information, and attack flow information included in the interface traffic; traffic association is to bind the terminal information and the tunnel information, and bind the tunnel information and the attack flow information, so that the terminal information and the attack flow information can be bound, thereby performing attack terminal traceability positioning.
[0061] In some exemplary embodiments, as Figure 4 shown, the terminal identity traceability method may include the following steps:
[0062] Step 401: Analyze the traffic of the session creation process of the N4 interface, and obtain the subscriber permanent identifier (SUPI), the TEID of the terminal's N3 interface uplink tunnel and the destination IP address of the uplink tunnel communication, the SEID of the current session process, and the session IP address (i.e., the destination IP address of the session modification request message).
[0063] Step 402: Analyze the traffic of the session modification process of the N4 interface, and obtain the SEID of the current session process and the destination IP address of the session modification request message (i.e., the IP address of the UPF network element), the TEID of the terminal's N3 interface downlink tunnel, and the destination IP address of the downlink tunnel communication.
[0064] Step 403: According to whether the SEID of the current session process obtained and the destination IP address of the session modification request message are consistent, associate the session creation process information and the session modification process information of the current terminal. By integrating the two pieces of information, the uplink tunnel information and the downlink tunnel information corresponding to the current terminal can be determined, and these information are saved here. Since the terminal will move, the corresponding tunnel information will also change, but the subscriber permanent identifier (SUPI) will not change. Therefore, we can perform real-time update according to the parsed data in accordance with the subscriber permanent identifier (SUPI).
[0065] Step 404: The service traffic of the terminal is sent from the base station to the UPF network element through the N3 interface using the GTP tunnel protocol. Here, it is necessary to strip the GTP tunnel protocol. During the stripping process, it is necessary to obtain the TEID value of the current tunnel traffic and the corresponding destination IP address of the tunnel communication, and then perform security monitoring on the payload data. Here, the information we need to extract includes the TEID of the tunnel, the destination IP address of the tunnel communication, and the five-tuple information of the tunnel payload flow.
[0066] Step 405: Now we can obtain the identity information of the terminal, the corresponding tunnel information, and the tunnel traffic load information from the 5G private network traffic. Therefore, it is only necessary to compare the tunnel identifier TEID obtained from the N3 interface and the destination IP address of the tunnel communication with the tunnel identifier TEID and the destination IP address of the tunnel communication in each terminal obtained from the N4 interface one by one. If the comparison is successful, the tunnel traffic load information corresponding to the terminal can be identified.
[0067] Step 406: If the network security device detects an attack flow in the 5G private network, extract the corresponding five-tuple information and the associated tunnel traffic load information of the terminal, and then query it to trace the terminal information of the attack flow.
[0068] The terminal identity tracing method provided by the present disclosure only needs to collect the traffic of the N3 interface and the N4 interface to perform traffic tracing in the service domain. The present disclosure is applicable to terminal tracing and positioning in the 5G private network environment. For example, it can be used to trace and position attack flows or any other traffic.
[0069] As Figure 5 shown, the embodiment of the present disclosure also provides a terminal identity tracing device, which may include a traffic parsing module 501, an information association module 502, and a security monitoring module 503, where:
[0070] The traffic parsing module 501 is responsible for parsing the traffic of the N3 interface and the N4 interface, and generating a terminal tunnel table and a tunnel load table respectively according to the parsed traffic information;
[0071] The information association module 502 is responsible for associating the terminal tunnel table and the tunnel load table generated by the traffic parsing module 501, generating a terminal load table for querying after association, and updating the terminal load table in real time according to changes; it is also responsible for receiving the five-tuple information of the attack flow output by the security monitoring module 503, and then querying the terminal according to the terminal load table, and outputting the terminal information corresponding to the attack flow;
[0072] The security monitoring module 503 is responsible for performing security monitoring on the tunnel traffic load of the N3 interface. If an attack is detected, it obtains the five-tuple information of the attack flow and sends it to the information association module 502.
[0073] In some exemplary embodiments, the session management process may include a session creation process, a session modification process, and a session deletion process. The traffic parsing module 501 parses the traffic of the N4 interface, which may include:
[0074] Parse the traffic of the session creation process of the N4 interface, record the identity information of the terminal, the uplink tunnel information assigned to the terminal, and the session layer information of the current session process;
[0075] Analyze the session modification process traffic of the N4 interface, and determine the downlink tunnel information of the terminal according to the session layer information of the current session process.
[0076] The embodiments of the present disclosure also provide a terminal identity traceability device, including a memory; and a processor connected to the memory, the processor being configured to execute the steps of the terminal identity traceability method as described in any of the preceding items based on the instructions stored in the memory.
[0077] In one example, as Figure 6 shown, the terminal identity traceability device may include: a processor 610, a memory 620, a bus system 630, and a transceiver 640. Among them, the processor 610, the memory 620, and the transceiver 640 are connected through the bus system 630. The memory 620 is used to store instructions, and the processor 610 is used to execute the instructions stored in the memory 620 to control the transceiver 640 to send signals. Specifically, the transceiver 640 can obtain the session management process traffic of the N4 interface and the service traffic of the N3 interface under the control of the processor 610. The processor 610 analyzes the session management process traffic of the N4 interface to establish a terminal tunnel table, and the terminal tunnel table is used to record the identity information of the terminal and the tunnel information assigned to the terminal; analyzes the service traffic of the N3 interface to establish a tunnel load table, and the tunnel load table is used to record the tunnel information and the load flow information of the tunnel; establishes a terminal load table according to the terminal tunnel table and the tunnel load table, and the terminal load table is used to record the identity information of the terminal and the load flow information corresponding to the terminal; detects the load flow information to be detected according to the terminal load table.
[0078] It should be understood that the processor 610 may be a central processing unit (CPU), and the processor 610 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor 610 may also be any conventional processor, etc.
[0079] The memory 620 may include a read-only memory and a random access memory, and provide instructions and data to the processor 610. A part of the memory 620 may also include a non-volatile random access memory. For example, the memory 620 may also store information about the device type.
[0080] In addition to the data bus, the bus system 630 may also include a power bus, a control bus, a status signal bus, etc.
[0081] In the implementation process, the processing performed by the terminal identity traceability device can be completed by the integrated logic circuit of the hardware in the processor 610 or the instructions in the form of software. That is, the method steps of the embodiments of the present disclosure can be embodied as being executed and completed by the hardware processor, or by a combination of the hardware and software modules in the processor 610. The software module can be located in a storage medium such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 620, and the processor 610 reads the information in the memory 620 and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.
[0082] The embodiments of the present disclosure also provide a computer storage medium. The computer storage medium stores executable instructions. When the executable instructions are executed by a processor, the terminal identity traceability method provided in any one of the above embodiments of the present disclosure can be implemented. The terminal identity traceability method can parse the session management process traffic of the N4 interface to establish a terminal tunnel table, where the terminal tunnel table is used to record the identity information of the terminal and the tunnel information assigned to the terminal; parse the service traffic of the N3 interface to establish a tunnel load table, where the tunnel load table is used to record the tunnel information and the load flow information of the tunnel; establish a terminal load table according to the terminal tunnel table and the tunnel load table, where the terminal load table is used to record the identity information of the terminal and the load flow information corresponding to the terminal; detect the load flow information to be detected according to the terminal load table, thereby realizing the terminal traceability and positioning in the 5G private network environment. The method of driving the terminal identity traceability by executing the executable instructions is basically the same as the terminal identity traceability method provided in the above embodiments of the present disclosure, and will not be elaborated here.
[0083] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof. In the hardware implementation, the division of the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all components can be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that a communication medium typically contains computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0084] Although the embodiments disclosed in this disclosure are as described above, the content described is only an embodiment adopted for the convenience of understanding this disclosure and is not intended to limit this disclosure. Any person skilled in the art within the scope of this disclosure can make any modifications and changes in the form and details of the implementation without departing from the spirit and scope disclosed in this disclosure. However, the protection scope of this disclosure shall still be subject to the scope defined by the appended claims.
Claims
1. A method for tracing the identity of a terminal, characterized in that, Applied to a terminal identity traceability device, the method includes: Analyze the session management process traffic of the N4 interface between the SMF network element and the UPF network element to establish a terminal tunnel table, which is used to record the identity information of the terminal and the tunnel information assigned to the terminal; the session management process includes a session creation process and a session modification process. The analysis of the session management process traffic of the N4 interface between the SMF network element and the UPF network element includes: analyzing the session creation process traffic of the N4 interface, recording the identity information of the terminal, the uplink tunnel information assigned to the terminal, and the session layer information of the current session process; analyzing the session modification process traffic of the N4 interface, and determining the downlink tunnel information of the terminal according to the session layer information of the current session process. Analyze the service traffic of the N3 interface between the base station and the UPF network element to establish a tunnel load table, which is used to record the tunnel information and the load flow information of the tunnel. Establish a terminal load table according to the terminal tunnel table and the tunnel load table, which is used to record the identity information of the terminal and the load flow information corresponding to the terminal. Detect the load flow information to be detected according to the terminal load table; the detection of the load flow information to be detected according to the terminal load table includes: performing a security detection on the tunnel load flow of the N3 interface between the base station and the UPF network element; when a security attack is detected, obtain the attack flow information; determine the terminal corresponding to the attack flow information according to the terminal load table.
2. The terminal identity traceability method according to claim 1, wherein, The uplink tunnel information includes the tunnel endpoint identifier of the uplink tunnel and the destination IP address of the uplink tunnel communication, and the downlink tunnel information includes the tunnel endpoint identifier of the downlink tunnel and the destination IP address of the downlink tunnel communication.
3. The terminal identity tracing method according to claim 1, wherein The session layer information of the current session process includes: the session endpoint identifier and the session IP address of the current session process.
4. The terminal identity traceability method according to claim 1, characterized in that, The load flow information includes the source IP address, the destination IP address, the source port number, and the destination port number.
5. The terminal identity traceability method according to claim 1, characterized in that The load flow information includes the source IP address, the destination IP address, the source port number, the destination port number, and the protocol number.
6. The method for tracing the identity of a terminal according to claim 1, wherein The identity information of the terminal includes the international mobile subscriber identification number or the user permanent identifier of the terminal.
7. A terminal identity traceability device, characterized in that, It includes a memory; and a processor connected to the memory, and the processor is configured to execute the steps of the terminal identity traceability method according to any one of claims 1 to 6 based on the instructions stored in the memory.
8. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the program is executed by the processor, it implements the terminal identity traceability method according to any one of claims 1 to 6.
Citation Information
Patent Citations
User information associated backfilling method and device based on 5G core network, equipment and medium
CN112738791A
Remote terminal device dynamic access method and apparatus
WO2019144719A1